Your message dated Thu, 15 Feb 2007 17:17:18 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#408948: fixed in nautilus 2.16.3-3
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--- Begin Message ---
Package: gnome-vfs2
Version: 2.14.2-4
Severity: serious
Tags: security
Hi,
This seems to be an old known problem / bug / vulnerability which is
described here:
<https://bugzilla.novell.com/show_bug.cgi?id=238503>
It affects GNOME but not Xfce and KDE which work with the same
shared-mime-info data. It seems the freedesktop.org XML database
provides "OR" type matching instead of "AND" type matching on the
a) extension and b) magic criterions found in the database (that is: it
is enough to match the magic of a desktop file to be considered one,
even if the extension is not .desktop).
Some interesting bits:
<http://lists.freedesktop.org/archives/xdg/2007-January/thread.html#9150>
This is a design issue with shared-mime-info, but should be worked
around in gnome-vfs2 (I think).
Bye,
-- System Information:
Debian Release: 4.0
APT prefers unstable
APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)
Shell: /bin/sh linked to /bin/bash
Kernel: Linux 2.6.18-3-686
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
--
Loïc Minier <[EMAIL PROTECTED]>
--- End Message ---
--- Begin Message ---
Source: nautilus
Source-Version: 2.16.3-3
We believe that the bug you reported is fixed in the latest version of
nautilus, which is due to be installed in the Debian FTP archive:
libnautilus-extension-dev_2.16.3-3_amd64.deb
to pool/main/n/nautilus/libnautilus-extension-dev_2.16.3-3_amd64.deb
libnautilus-extension1_2.16.3-3_amd64.deb
to pool/main/n/nautilus/libnautilus-extension1_2.16.3-3_amd64.deb
nautilus-data_2.16.3-3_all.deb
to pool/main/n/nautilus/nautilus-data_2.16.3-3_all.deb
nautilus-dbg_2.16.3-3_amd64.deb
to pool/main/n/nautilus/nautilus-dbg_2.16.3-3_amd64.deb
nautilus_2.16.3-3.diff.gz
to pool/main/n/nautilus/nautilus_2.16.3-3.diff.gz
nautilus_2.16.3-3.dsc
to pool/main/n/nautilus/nautilus_2.16.3-3.dsc
nautilus_2.16.3-3_amd64.deb
to pool/main/n/nautilus/nautilus_2.16.3-3_amd64.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Josselin Mouette <[EMAIL PROTECTED]> (supplier of updated nautilus package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Thu, 15 Feb 2007 17:23:51 +0100
Source: nautilus
Binary: libnautilus-extension-dev libnautilus-extension1 nautilus-data
nautilus-dbg nautilus
Architecture: source amd64 all
Version: 2.16.3-3
Distribution: experimental
Urgency: low
Maintainer: Josselin Mouette <[EMAIL PROTECTED]>
Changed-By: Josselin Mouette <[EMAIL PROTECTED]>
Description:
libnautilus-extension-dev - libraries for nautilus components - development
version
libnautilus-extension1 - libraries for nautilus components - runtime version
nautilus - file manager and graphical shell for GNOME
nautilus-data - data files for nautilus
nautilus-dbg - file manager and graphical shell for GNOME - debugging version
Closes: 230757 408556 408896 408948
Changes:
nautilus (2.16.3-3) experimental; urgency=low
.
[ Loic Minier ]
* Add a get-orig-source target to retrieve the upstream tarball.
* Add an epoch to the libgnomevfs2-dev build-dep and dep.
* Include the new check-dist Makefile to prevent accidental uploads to
unstable; bump build-dep on gnome-pkg-tools to >= 0.10.
.
[ Josselin Mouette ]
* 06_dont_create_Desktop.patch: patch from upstream bugzilla. Don't
create the Desktop directory when run with the --no-desktop option
(closes: #230757, #408896).
* 07_desktop_file_activation.patch:
+ Don't launch desktop files that aren't at safe places
(closes: #408556). This doesn't affect desktop files that are
merely links.
+ Don't launch those that don't end with .desktop (closes: #408948).
Files:
b32ea681751c9c4ffb5968103cef7061 2051 gnome optional nautilus_2.16.3-3.dsc
0c3697ade29bc42ef4da32e5306e4064 28809 gnome optional nautilus_2.16.3-3.diff.gz
fcfdc9830514b0e77777c4f45db0f6b6 3818402 gnome optional
nautilus-data_2.16.3-3_all.deb
8f08288b5d3344286e79700f43a96f62 656170 gnome optional
nautilus_2.16.3-3_amd64.deb
cf31cfb75b2bfbef08046ae5698f316f 1780282 gnome extra
nautilus-dbg_2.16.3-3_amd64.deb
32795f7caf187fd1b6d2f0b53b8eff95 96202 libs optional
libnautilus-extension1_2.16.3-3_amd64.deb
7fb479bf876a18988f6b80e18657599b 89616 libdevel optional
libnautilus-extension-dev_2.16.3-3_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFF1JFmrSla4ddfhTMRArycAJ9O2qR+kLoeHzUOaziQ1lbzuDQPtQCg0sVd
DUyijVrET3JAOh/lK51rBZ4=
=/KiK
-----END PGP SIGNATURE-----
--- End Message ---